A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data. Under HIPAA, does this vendor require a BAA?
-
A
No, because it cannot decrypt the PHI
-
B
Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity
-
C
Only if the vendor is based in the United States
-
D
Only if the covered entity has more than 500 patients